Skip to content

The 22 Amazon Bedrock security checks Black Cat runs

Black Cat SSPM evaluates 22 security policies against your Amazon Bedrock configuration on every scan, classifies each finding by risk, and provides remediation steps. Browse them by topic below.

How to connect Amazon Bedrock — what access Black Cat needs, and why.

Access control & privilege (4)

Data sharing & exposure (4)

Configuration hardening (4)

AI governance (5)

Lifecycle & offboarding (4)

Other checks (1)

severity: medium Bedrock Model Invocation Logging Disabled fix difficulty: easy #

Enable model invocation logging to CloudWatch or S3

  1. Open AWS Bedrock Console > Settings
  2. Enable Model invocation logging
  3. Choose a CloudWatch log group and/or S3 bucket destination

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.b.2 DORA (SaaS Security) DORA-10.1

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial